Operate
Production deployment
A checklist for going live.
Checklist#
- Use the production environment's client ID and API key, and set
AUTH_API_URL. - Keep
AUTH_API_KEYand anywhsec_…secret in your host's secret store, never in aNEXT_PUBLIC_variable. - Register your production callback URL (HTTPS) as a redirect URI, and remove any you no longer use.
- Choose session and access-token lifetimes, and the MFA mode, for the production environment.
- Set branding and, if you use one, verify your custom domain.
- Add webhook endpoints and watch for dead deliveries.
- Sign in, sign out and reset a password once end to end before announcing it.
What fails closed#
- No
AUTH_API_URLin production: the SDK throws on the first request instead of authenticating against the development API. - No client ID: the middleware refuses protected routes with
500and says why, instead of looping through sign-in. - Signing keys unreachable: sessions are treated as invalid, never trusted without a check.
- Cloudflare unreachable: checked submissions on the hosted pages are refused.